Shilpisoft
Shilpisoft Client Dashboard: vulnerabilidades y CVE
Shilpisoft Client Dashboard tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-47656 | Crítica (9.3) | 0.51% | — | 4 oct 2024 | This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack… |
| CVE-2024-47655 | Alta (8.6) | 0.69% | — | 4 oct 2024 | This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by… |
| CVE-2024-47654 | Alta (7.1) | 0.49% | — | 4 oct 2024 | This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by… |
| CVE-2024-47653 | Alta (7.1) | 0.34% | — | 4 oct 2024 | This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requests through certain API endpoints. An authenticated remote attacker could exploit this… |
| CVE-2024-47652 | Alta (7.6) | 0.41% | — | 4 oct 2024 | This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their corresponding mobile… |